Skip to main content

My company security team audited the Tableau and found, that specific password policy is not possible to be configured: 

 

New passwords checked against the history of the last 5 passwords and rejected if there is a match

 

Can we request to add such password history check feature in Tableau Server Cloud?  

Extend password policy with history

 

 

 

#Tableau Server

1 Antwort
  1. 31. Aug., 17:09

    Hi Krzysztof, short answer, neither Tableau Server nor Tableau Cloud local authentication supports a password-history or reuse-prevention rule, so that specific control cannot be configured natively. The local password policy only covers minimum and maximum length, character complexity (letters, mixed case, numbers, symbols), password expiration, and account lockout after failed logins, there is no setting to reject reuse of the last N passwords. 

     

    The standard way to satisfy that audit finding is to move authentication off local auth and onto an external identity provider, SAML SSO, or Active Directory LDAP for Server. Then your corporate password policy, including the last-5-passwords history rule, is enforced upstream at the IdP or AD, and Tableau simply honors that login. This is how most enterprises meet exactly this kind of security-team requirement. 

     

    For the feature request itself, password history is not available as a native local-auth setting, so the place to raise it is the Tableau Ideas site, but an external IdP is the supported path today. 

     

    if this helps, please mark it as the Best Answer so it helps the next person, thanks 🙂

0/9000